GHSA-7rw2-3hhp-rc46
Cross-site Scripting Vulnerability in Statement Browser
Quick fix
GHSA-7rw2-3hhp-rc46 — com.yetanalytics:lrs: upgrade to the fixed version with the command below.
# pom.xml: bump <version>1.2.17</version> for com.yetanalytics:lrsDetails
### Impact A maliciously crafted xAPI statement could be used to perform script or other tag injection in the LRS Statement Browser.
### Patches The problem is patched in version 1.2.17 of the LRS library and [version 0.7.5 of SQL LRS](https://github.com/yetanalytics/lrsql/releases/tag/v0.7.5).
### Workarounds No workarounds exist, we recommend upgrading to version 1.2.17 of the library or version 0.7.5 of SQL LRS immediately.
### References * [LRS Tag](https://github.com/yetanalytics/lrs/releases/tag/v1.2.17) * [LRS lib on Clojars](https://clojars.org/com.yetanalytics/lrs/versions/1.2.17) * [SQL LRS 0.7.5 Release](https://github.com/yetanalytics/lrsql/releases/tag/v0.7.5)
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 1.2.17# pom.xml: bump <version>1.2.17</version> for com.yetanalytics:lrsReferences
- https://github.com/yetanalytics/lrs/security/advisories/GHSA-7rw2-3hhp-rc46[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2024-26140[ADVISORY]
- https://github.com/yetanalytics/lrs/commit/d7f4883bc2252337d25e8bba2c7f9d172f5b0621[WEB]
- https://clojars.org/com.yetanalytics/lrs/versions/1.2.17[WEB]
- https://github.com/yetanalytics/lrs[PACKAGE]
- https://github.com/yetanalytics/lrs/releases/tag/v1.2.17[WEB]
- https://github.com/yetanalytics/lrsql/releases/tag/v0.7.5[WEB]